I started having suspicious that the computer have a malware when I saw the message on startup "the memory could not be 'read'", and "tavo.exe" or "kavo.exe" or "2.exe" written in the same windows..
The strange thing is that my "Avast antivirus" haven`t found ANYTHING suspicious in the scans I made, but kapersky online scanner found a lot!
HJT log (AFTER I installed Spybot, and fixed everything in red on secure mode)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:10:38, on 7/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\VM_STI.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Palm\Hotsync.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Usuario\CONFIG~1\Temp\ff.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIV~1\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE A4 Tech USB PC Camera
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [tava] C:\WINDOWS\system32\tavo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Palm Registration.lnk = C:\Arquivos de programas\Palm\register.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Arquivos de programas\Palm\Hotsync.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O15 - Trusted Zone: http://www.catarinense.net
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399003} (GbPluginObj Class) - https://imagem.caixa.gov.br/cab/GbPluginCef.cab
O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GBPLUGIN\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O20 - Winlogon Notify: __GbPluginBb - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 8079 bytes
Kapersky online scanner (scanned BEFORE I installed spybot and corrected some things)
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 06, 2008 10:56:20 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 742492
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 122152
Number of viruses found: 31
Number of infected objects: 121
Number of suspicious objects: 0
Duration of the scan process: 01:48:56
Infected Object Name / Virus Name / Last Action
C:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\report\Proteção residente.txt Object is locked skipped
C:\Arquivos de programas\BrainWave Generator\BrainWave.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Arquivos de programas\eMule\Incoming\Absolute.Fretboard.Trainer.3.x.kmaker.zip/Absolute.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Arquivos de programas\eMule\Incoming\Absolute.Fretboard.Trainer.3.x.kmaker.zip ZIP: infected - 1 skipped
C:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Histórico\History.IE5\MSHist012008050620080507\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\9b2ek.dll Infected: Trojan-PSW.Win32.OnLineGames.acka skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\ac7.dll Infected: Trojan-PSW.Win32.OnLineGames.acka skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\cny8p.dll Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\ff.exe Infected: Trojan-PSW.Win32.OnLineGames.adnp skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\generator.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\gm2djq.dll Infected: Trojan-PSW.Win32.OnLineGames.aded skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\if.dll Infected: Trojan-PSW.Win32.OnLineGames.abbj skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\mt7w.dll Infected: Trojan-PSW.Win32.OnLineGames.adej skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru1.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru2.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru3.tmp Infected: Worm.Win32.AutoRun.dkf skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru32.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru33.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru4.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru5.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru6.tmp Infected: Trojan-PSW.Win32.OnLineGames.adnp skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\truE5.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\truE7.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tw4nfj.dll Infected: Trojan-PSW.Win32.OnLineGames.adns skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\un.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxy skipped
C:\Documents and Settings\Usuario\Configurações locais\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\cert8.db Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\history.dat Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\key3.db Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\parent.lock Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Usuario\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Usuario\ntuser.dat.LOG Object is locked skipped
C:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071696.dll Infected: Trojan-PSW.Win32.OnLineGames.aazm skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071698.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071815.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071816.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071818.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071826.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071831.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071873.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071875.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071883.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071925.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071927.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071943.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071944.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071946.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071954.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072008.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072010.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072011.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083814.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083815.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083816.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083823.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083824.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083835.dll Infected: Trojan-PSW.Win32.OnLineGames.adeb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083838.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083846.exe Infected: Trojan-PSW.Win32.OnLineGames.adec skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083847.dll Infected: Trojan-PSW.Win32.OnLineGames.abal skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083859.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083862.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083870.exe Infected: Trojan-PSW.Win32.OnLineGames.adec skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083871.dll Infected: Trojan-PSW.Win32.OnLineGames.adeb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083914.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083932.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083935.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083958.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083959.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083962.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\kavo.exe Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\WINDOWS\system32\kavo0.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\WINDOWS\system32\kavo1.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\WINDOWS\system32\tavo.exe Infected: Trojan.Win32.Vaklik.agh skipped
C:\WINDOWS\system32\tavo0.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\WINDOWS\system32\tavo1.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_5f0.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071699.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071820.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071833.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071877.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071929.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071948.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072012.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072013.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083818.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083840.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083864.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083916.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083937.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083964.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
F:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
F:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054954.dll Infected: not-a-virus:AdWare.Win32.WinAD.am skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe/ci-temp0.cab/Sp0.exe Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe/ci-temp0.cab Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe CreateInstall: infected - 2 skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071700.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071822.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071835.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071879.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071931.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071950.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072014.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072015.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP527\A0073108.exe Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083820.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083842.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083866.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083918.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083939.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083966.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0006 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe Inno: infected - 3 skipped
F:\mirc6\miRC 6\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
F:\mirc6\outd\mirc32.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.59 skipped
F:\mirc6\outd\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
F:\mirc6\outd.zip/mirc32.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.59 skipped
F:\mirc6\outd.zip ZIP: infected - 1 skipped
Scan process completed.
Thank´s for the future help I`m sure I`m gonna get (as I had once before
)
The strange thing is that my "Avast antivirus" haven`t found ANYTHING suspicious in the scans I made, but kapersky online scanner found a lot!
HJT log (AFTER I installed Spybot, and fixed everything in red on secure mode)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:10:38, on 7/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\VM_STI.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Palm\Hotsync.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Usuario\CONFIG~1\Temp\ff.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIV~1\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE A4 Tech USB PC Camera
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [tava] C:\WINDOWS\system32\tavo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Palm Registration.lnk = C:\Arquivos de programas\Palm\register.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Arquivos de programas\Palm\Hotsync.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O15 - Trusted Zone: http://www.catarinense.net
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399003} (GbPluginObj Class) - https://imagem.caixa.gov.br/cab/GbPluginCef.cab
O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GBPLUGIN\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O20 - Winlogon Notify: __GbPluginBb - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 8079 bytes
Kapersky online scanner (scanned BEFORE I installed spybot and corrected some things)
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 06, 2008 10:56:20 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 742492
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 122152
Number of viruses found: 31
Number of infected objects: 121
Number of suspicious objects: 0
Duration of the scan process: 01:48:56
Infected Object Name / Virus Name / Last Action
C:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Arquivos de programas\Alwil Software\Avast4\DATA\report\Proteção residente.txt Object is locked skipped
C:\Arquivos de programas\BrainWave Generator\BrainWave.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Arquivos de programas\eMule\Incoming\Absolute.Fretboard.Trainer.3.x.kmaker.zip/Absolute.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Arquivos de programas\eMule\Incoming\Absolute.Fretboard.Trainer.3.x.kmaker.zip ZIP: infected - 1 skipped
C:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Histórico\History.IE5\MSHist012008050620080507\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\9b2ek.dll Infected: Trojan-PSW.Win32.OnLineGames.acka skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\ac7.dll Infected: Trojan-PSW.Win32.OnLineGames.acka skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\cny8p.dll Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\ff.exe Infected: Trojan-PSW.Win32.OnLineGames.adnp skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\generator.exe Infected: Trojan.Win32.Agent.acw skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\gm2djq.dll Infected: Trojan-PSW.Win32.OnLineGames.aded skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\if.dll Infected: Trojan-PSW.Win32.OnLineGames.abbj skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\mt7w.dll Infected: Trojan-PSW.Win32.OnLineGames.adej skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru1.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru2.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru3.tmp Infected: Worm.Win32.AutoRun.dkf skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru32.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru33.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru4.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru5.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tru6.tmp Infected: Trojan-PSW.Win32.OnLineGames.adnp skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\truE5.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\truE7.tmp Infected: Trojan-PSW.Win32.OnLineGames.adds skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\tw4nfj.dll Infected: Trojan-PSW.Win32.OnLineGames.adns skipped
C:\Documents and Settings\Usuario\Configurações locais\Temp\un.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxy skipped
C:\Documents and Settings\Usuario\Configurações locais\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Usuario\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\cert8.db Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\history.dat Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\key3.db Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\parent.lock Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\7dyho099.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Usuario\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Usuario\ntuser.dat.LOG Object is locked skipped
C:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071696.dll Infected: Trojan-PSW.Win32.OnLineGames.aazm skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071698.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071815.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071816.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071818.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071826.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071831.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071873.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071875.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071883.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071925.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071927.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071943.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071944.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071946.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071954.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072008.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072010.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072011.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083814.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083815.dll Infected: Trojan-PSW.Win32.OnLineGames.aaxw skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083816.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083823.exe Infected: Trojan-PSW.Win32.OnLineGames.aayb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083824.dll Infected: Trojan-PSW.Win32.OnLineGames.acwh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083835.dll Infected: Trojan-PSW.Win32.OnLineGames.adeb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083838.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083846.exe Infected: Trojan-PSW.Win32.OnLineGames.adec skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083847.dll Infected: Trojan-PSW.Win32.OnLineGames.abal skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083859.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083862.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083870.exe Infected: Trojan-PSW.Win32.OnLineGames.adec skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083871.dll Infected: Trojan-PSW.Win32.OnLineGames.adeb skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083914.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083932.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083935.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083958.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083959.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083962.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\kavo.exe Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
C:\WINDOWS\system32\kavo0.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\WINDOWS\system32\kavo1.dll Infected: Trojan-PSW.Win32.OnLineGames.adeh skipped
C:\WINDOWS\system32\tavo.exe Infected: Trojan.Win32.Vaklik.agh skipped
C:\WINDOWS\system32\tavo0.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\WINDOWS\system32\tavo1.dll Infected: Trojan-PSW.Win32.OnLineGames.adnr skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_5f0.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071699.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071820.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071833.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071877.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071929.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071948.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072012.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072013.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083818.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083840.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083864.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083916.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083937.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083964.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
E:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
F:\lgcadwx.bat Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
F:\c.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054954.dll Infected: not-a-virus:AdWare.Win32.WinAD.am skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe/ci-temp0.cab/Sp0.exe Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe/ci-temp0.cab Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{CF3380D7-62D1-4B19-96F4-B29436459BC0}\RP300\A0054955.exe CreateInstall: infected - 2 skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071700.inf Infected: Trojan-PSW.Win32.OnLineGames.zta skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP525\A0071822.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071835.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071879.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071931.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0071950.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072014.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP526\A0072015.inf Infected: Trojan-PSW.Win32.OnLineGames.abes skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP527\A0073108.exe Infected: Trojan-Spy.Win32.Outside.12 skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083820.com Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083842.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP538\A0083866.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083918.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083939.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\change.log Object is locked skipped
F:\System Volume Information\_restore{85F572D8-1212-4939-A61B-7A9E43480252}\RP539\A0083966.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\2y8la.exe Infected: Trojan-PSW.Win32.OnLineGames.aaxz skipped
F:\0qx0sc6.bat Infected: Trojan-PSW.Win32.OnLineGames.adei skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe/data0006 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\ProgrAmAs\vnc-4.0-x86_win32.exe Inno: infected - 3 skipped
F:\mirc6\miRC 6\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
F:\mirc6\outd\mirc32.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.59 skipped
F:\mirc6\outd\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
F:\mirc6\outd.zip/mirc32.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.59 skipped
F:\mirc6\outd.zip ZIP: infected - 1 skipped
Scan process completed.
Thank´s for the future help I`m sure I`m gonna get (as I had once before
